Privacy notices -report publishing and maintenance

Critical
High
Normal
Low

With regard to the processing of personal data, the data subject must be provided with the information specified in the GDPR in a concise, comprehensible and easily accessible form. This is often done in the form of privacy statements, which are published, for example, on the organisation's website.

Where personal data have not been collected from the data subject himself, the descriptions shall state, in addition to the basic content:

  • where the data were obtained
  • which categories of personal data are covered
Connected other frameworks and requirements:
14. Information to be provided where personal data have not been obtained from the data subject
GDPR
12. Transparent information, communication and modalities for the exercise of the rights of the data subject
GDPR
13. Information to be provided where personal data are collected from the data subject
GDPR
18.1.4: Privacy and protection of personally identifiable information
A.12.1: Geographical location of PII
ISO 27018

Documentation of personal data sources for data systems

Critical
High
Normal
Low

Understanding data sources is important for understanding data flow. In addition, data protection communications shall be able to communicate the sources of personal data in cases where the data have not been collected directly from the data subject himself.

Connected other frameworks and requirements:
14. Information to be provided where personal data have not been obtained from the data subject
GDPR
A.7.3.3: Providing information to PII principals
ISO 27701
No items found.